Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-53705

Опубликовано: 15 июн. 2026
Источник: debian
EPSS Низкий

Описание

A flaw was found in GStreamer's WavPack audio decoder in gst-plugins-good. When processing a specially crafted WavPack file, an integer overflow in the buffer size calculation (4 * block_samples * channels) in gst_wavpack_dec_handle_frame() causes a very small heap allocation. The WavPack library then writes decoded audio samples far beyond the allocated buffer, resulting in heap memory corruption. This affects both 32-bit and 64-bit systems since the arithmetic is performed in 32-bit integers before promotion to the allocation size type. A remote attacker could use this flaw to crash an application or potentially execute arbitrary code by convincing a user to open a malicious WavPack audio file.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
gst-plugins-good1.0fixed1.28.4-1package
gst-plugins-good1.0no-dsatrixiepackage

Примечания

  • https://gstreamer.freedesktop.org/security/sa-2026-0035.html

  • https://gitlab.freedesktop.org/gstreamer/gstreamer/-/work_items/5069

  • https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/11797

  • https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/11811

  • Fixed by: https://gitlab.freedesktop.org/gstreamer/gstreamer/-/commit/ed09b692755e251e730f35126ff6eab27cb8edc5 (1.28.4)

  • Fixed by: https://gitlab.freedesktop.org/gstreamer/gstreamer/-/commit/e9ded43316bfe6c381a17f971c7097421a4ae201 (1.28.4)

  • Fixed by: https://gitlab.freedesktop.org/gstreamer/gstreamer/-/commit/9326c636a22a678952a6cae6518465d35d441a87 (1.28.4)

  • Fixed by: https://gitlab.freedesktop.org/gstreamer/gstreamer/-/commit/f7cb3e0288627cce919e656584b852ac8605c922 (1.28.4)

EPSS

Процентиль: 29%
0.00361
Низкий

Связанные уязвимости

CVSS3: 7.6
ubuntu
около 2 месяцев назад

A flaw was found in GStreamer's WavPack audio decoder in gst-plugins-good. When processing a specially crafted WavPack file, an integer overflow in the buffer size calculation (4 * block_samples * channels) in gst_wavpack_dec_handle_frame() causes a very small heap allocation. The WavPack library then writes decoded audio samples far beyond the allocated buffer, resulting in heap memory corruption. This affects both 32-bit and 64-bit systems since the arithmetic is performed in 32-bit integers before promotion to the allocation size type. A remote attacker could use this flaw to crash an application or potentially execute arbitrary code by convincing a user to open a malicious WavPack audio file.

CVSS3: 7.6
redhat
около 2 месяцев назад

A flaw was found in GStreamer's WavPack audio decoder in gst-plugins-good. When processing a specially crafted WavPack file, an integer overflow in the buffer size calculation (4 * block_samples * channels) in gst_wavpack_dec_handle_frame() causes a very small heap allocation. The WavPack library then writes decoded audio samples far beyond the allocated buffer, resulting in heap memory corruption. This affects both 32-bit and 64-bit systems since the arithmetic is performed in 32-bit integers before promotion to the allocation size type. A remote attacker could use this flaw to crash an application or potentially execute arbitrary code by convincing a user to open a malicious WavPack audio file.

CVSS3: 7.6
nvd
около 2 месяцев назад

A flaw was found in GStreamer's WavPack audio decoder in gst-plugins-good. When processing a specially crafted WavPack file, an integer overflow in the buffer size calculation (4 * block_samples * channels) in gst_wavpack_dec_handle_frame() causes a very small heap allocation. The WavPack library then writes decoded audio samples far beyond the allocated buffer, resulting in heap memory corruption. This affects both 32-bit and 64-bit systems since the arithmetic is performed in 32-bit integers before promotion to the allocation size type. A remote attacker could use this flaw to crash an application or potentially execute arbitrary code by convincing a user to open a malicious WavPack audio file.

suse-cvrf
25 дней назад

Security update for gstreamer-plugins-good

suse-cvrf
21 день назад

Security update for gstreamer-plugins-good

EPSS

Процентиль: 29%
0.00361
Низкий